VYPR

ElementsKit Elementor addons

by WordPress

CVEs (22)

  • CVE-2026-13393LowJul 31, 2026
    risk 0.00cvss 3.5epss 0.00

    The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not sanitize or escape certain megamenu menu-item settings before storing them and outputting them on the front end, and does not require the unfiltered_html capability to save them, allowing users with…

  • CVE-2026-13392HigJul 31, 2026
    risk 0.00cvss 7.2epss 0.00

    The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative capabilities from being written verbatim into a generated PHP file that the ElementsKit Elementor Addons WordPress plugin before…

Page 2 of 2